PULSE NAME
TanStack npm Packages Compromised in Ongoing Supply-Chain Attack
WHITE TeamPCP AlienVault 2026-05-12 Modified: 2026-05-12
9
IOCs
LOW VOLUME
Socket detected 84 compromised TanStack npm package artifacts modified with credential-stealing malware targeting CI systems, including GitHub Actions. Affected packages like @tanstack/react-router have over 12 million weekly downloads. The malicious versions contain router_init.js, a heavily obfuscated file with daemonization capabilities and environment variable access for GitHub Actions secrets. The compromise exploited GitHub Actions cache poisoning and pull_request_target patterns to extract OIDC tokens and authenticate malicious npm publishes through trusted-publisher bindings. The malware harvests credentials from GitHub Actions, AWS (IMDS, Secrets Manager, SSM), HashiCorp Vault, and Kubernetes, while establishing persistence in Claude Code and VS Code directories. Exfiltration occurs through Session's decentralized P2P network. The campaign includes self-propagation mechanisms that steal npm OIDC tokens and autonomously republish compromised packages. Updates indicate expansion to OpenSearch, Mistr...
Indicators of Compromise (9)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 833fd59ebe66a4449982c6d18db656b4 2026-05-12
FileHash-MD5 b82e54923f7e440664d2d75bd31588ca 2026-05-12
FileHash-SHA1 12ed9a3c1f73617aefdb740480695c04405d7b4b 2026-05-12
FileHash-SHA1 79ac49eedf774dd4b0cfa308722bc463cfe5885c 2026-05-12
FileHash-SHA1 e7d582b98ca80690883175470e96f703ef6dc497 2026-05-12
FileHash-SHA256 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96 2026-05-12
FileHash-SHA256 ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c 2026-05-12
URL https://git-tanstack.com/transformers.pyz 2026-05-12
domain git-tanstack.com 2026-05-12